Senior Information Security

Il y a 3 jours

Ukkel, Brussel-Hoofdstad, Belgique Adjugo Temps plein 90 000 € - 150 000 €/an

Senior Information Security & NIS2 Compliance Consultant (Senior) - SMALS

SMALS is seeking a senior consultant to guide an organization toward compliance with the Belgian NIS2 obligations arising from the law of 26 April 2024. The assignment focuses on supporting the implementation of an information security policy and its associated technical and organizational measures. The consultant will work closely with the organization and its suppliers. Policies must be developed, aligned and implemented effectively.

The consultant will prepare and support the organization for audits, inspections and supervisory activities. A key objective is to ensure that the organization can demonstrate compliance with the applicable NIS2 obligations through evidence and documentation. The consultant will monitor progress and report it to the relevant stakeholders. The role therefore combines information security expertise, compliance work and stakeholder coordination.

The profile requires extensive experience in complex enterprise IT environments and at least five years in information security. Strong knowledge of NIS2, its Belgian transposition, CyberFundamentals and related information-security frameworks is expected. The consultant must balance cybersecurity risks against operational objectives and translate theory into practical, effective measures. Independence, leadership, persuasion and strong communication across internal and external stakeholders are essential.

Top Reasons to Apply

Lead NIS2 compliance

Shape security policy

Audit readiness ownership

Long-term hybrid assignment

Responsibilities

  • Guide NIS2 compliance
  • Implement security policy
  • Implement security measures
  • Collaborate with suppliers
  • Develop security policies
  • Harmonize security policies
  • Implement security policies

Must Have

  • 10+ years enterprise IT
  • 5+ years information security
  • Progress reporting experience

Nice to Have

  • ISO/IEC 27001 experience
  • Public sector experience
  • Social security experience

Detailed Responsibilities and Skills

Additional Responsibilities

  • Support inspection activities
  • Support supervisory activities
  • Demonstrate NIS2 compliance
  • At least 10 years of experience in complex enterprise-level IT environments.
  • At least 5 years of experience in information security in an operational or organizational context.
  • Experience in project management.
  • Experience in stakeholder management.
  • Experience in progress monitoring and reporting.
  • Experience preparing, supporting and following up audits.
  • Experience preparing, supporting and following up inspections.
  • Experience preparing, supporting and following up supervisory/control procedures.
  • Ability to balance cybersecurity risks against operational objectives and communicate about them clearly and convincingly.
  • Ability to demonstrate compliance through evidence and documentation to auditors and supervisory authorities.
  • Pragmatic approach that translates theoretical principles into feasible and effective measures.
  • Ability to work independently.
  • Strong expertise, leadership and persuasive ability.
  • Excellent communication skills and ability to collaborate with diverse internal and external stakeholders.
  • Active knowledge of Dutch.
  • Active knowledge of English.
  • Active knowledge of French.
  • Public-sector experience is a strong asset.
  • Social-security-sector experience is a strong asset.

Technical skills

  • Demonstrable experience implementing and rolling out an Information Security Management System (ISMS).
  • In-depth knowledge of the NIS2 Directive.
  • In-depth knowledge of the Belgian transposition of NIS2.
  • In-depth knowledge of the CyberFundamentals framework (CCB).
  • In-depth knowledge of related information-security frameworks.
  • Good understanding of technical security measures and their practical application in organizations.
  • Good understanding of organizational security measures and their practical application in organizations.
  • Experience with ISO/IEC 27001 is preferred.